IP Library Granted Patent US 12,277,248
Granted Patent B2
US 12,277,248 · App. 17/945,543 · Granted Apr 15, 2025

Methods and systems for managing user data privacy

Inventors: Kazuya Saginawa (Tokyo, JP); Tõnu Samuel (Räpina, EE); Jorge Quinteros (Santiago, CL); Saksham Kukreja (Dubai, AE); Yuet Fong (Hong Kong, HK)
Assignee: DataGateway Inc.
G06F21/6245G06F21/602G06F2221/2111
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,277,248
App. No.
17/945,543
Granted
Apr 15, 2025
Kind
B2
Abstract

A method may include storing, using a data management application on a user device, personal data that is associated with a user and a first data variable. The method may further include obtaining, from a requesting application and by the data management application, a data request for a second data variable. The method may further include determining, by the data management application, whether the first data variable associated with the personal data matches the second data variable associated with the data request. The method may further include transmitting, by the data management application and in response to determining that the first data variable matches the second data variable, the personal data to various intermediary nodes. One intermediary node among the intermediary nodes may transmit the personal data to the requesting application using a distributed ledger.

Claims (57)

1. A system, comprising:

a plurality of user devices comprising a first user device,

wherein the first user device comprises a first hardware processor, a first cryptographic key, and first personal data associated with a first user and a first data variable;

a node coupled to the plurality of user devices and comprising a second hardware processor; and

a plurality of intermediary nodes coupled to the plurality of user devices and the node, the plurality of intermediary nodes implementing a distributed ledger,

wherein the node is configured to transmit a broadcast request to the plurality of user devices, the broadcast request comprising a first data request associated with the first data variable,

wherein the first user device is configured to transmit, in response to receiving the broadcast request, encrypted data to the plurality of intermediary nodes based on the first personal data and the first cryptographic key, and

wherein the plurality of intermediary nodes are configured to transmit the encrypted data to the node using the distributed ledger.

2. The system of claim 1 , further comprising:

a second user device coupled to the plurality of intermediary nodes and comprising a data management application,

wherein the data management application is configured to:

store second personal data associated with a second data variable and a predefined response associated with the second data variable, and

transmit the second personal data to the plurality of intermediary nodes automatically in response to a second data request associated with the second data variable and based on the predefined response.

3. The system of claim 1 , further comprising:

a second user device coupled to the plurality of intermediary nodes and comprising a data management application,

wherein the data management application is configured to:

store second personal data and a plurality of predefined responses associated with a plurality of data variables,

obtain a second data request for a second data variable,

determine whether the second data request corresponds to the second data variable that matches at least one data variable associated with at least one predefined response among the plurality of predefined responses, and

present, in response to the second data request failing to match the at least one data variable, a notification on a display device requesting authorization to transmit the second personal data.

4. The system of claim 1 , further comprising:

a publisher-subscriber network comprising the plurality of user devices and the node,

wherein the plurality of user devices are subscriber nodes within the publisher-subscriber network,

wherein the node is a publishing node within the publisher-subscriber network, and

wherein the node is configured to use a publisher-subscriber network protocol to transmit one or more broadcast requests over the publisher-subscriber network.

5. The system of claim 1 ,

wherein the plurality of intermediary nodes are a plurality of blockchain nodes,

wherein the plurality of blockchain nodes are configured to validate a plurality of data transactions comprising a first data transaction and a second data transaction,

wherein the first data transaction corresponds to the first user device transmitting the encrypted data to the plurality of blockchain nodes, and

wherein the second data transaction corresponds to the plurality of blockchain nodes transmitting the encrypted data to the node.

6. The system of claim 1 ,

wherein the distributed ledger comprises a smart contract,

wherein a respective intermediary node among the plurality of intermediary nodes is configured to execute the smart contract in response to receiving the encrypted data, and

wherein the respective intermediary node is further configured to relay the encrypted data to the node based on a location address that is stored in the smart contract.

7. The system of claim 1 ,

wherein the distributed ledger is selected from a group consisting of a private blockchain, a public blockchain, a hybrid blockchain, a hashgraph, and a directed acyclic graph.

8. The system of claim 1 ,

wherein the first data variable is selected from a group consisting of a gender, a sexual orientation, an ethnic origin, and a political affiliation.

9. A method, comprising:

transmitting, by a node comprising a hardware processor, a broadcast request to a plurality of user devices on a publisher-subscriber network, wherein the broadcast request comprises a data request regarding a data variable;

obtaining, by the node and in response to the broadcast request, personal data from a plurality of intermediary nodes coupled to the publisher-subscriber network,

wherein the node is a publishing node and the plurality of user devices are subscriber nodes,

wherein the plurality of intermediary nodes implement a distributed ledger, and

wherein the plurality of intermediary nodes transmit the personal data to the node in response to the plurality of intermediary nodes validating a data transaction associated with the personal data using the distributed ledger.

10. The method of claim 9 , further comprising:

decrypting encrypted data using a public cryptographic key to produce decrypted data,

wherein the decrypted data corresponds to the personal data that is obtained by the node.

11. The method of claim 9 ,

wherein the distributed ledger comprises a smart contract,

wherein a respective intermediary node among the plurality of intermediary nodes is configured to execute the smart contract in response to receiving the personal data, and

wherein the respective intermediary node is further configured to relay the personal data to the node based on a network location address that is stored in the smart contract.

12. The method of claim 9 ,

wherein the distributed ledger is selected from a group consisting of a private blockchain, a public blockchain, a hybrid blockchain, a hashgraph, and a directed acyclic graph.

13. The method of claim 9 ,

wherein the data transaction is validated by determining whether a requesting application on the node is authorized to receive the personal data from the plurality of intermediary nodes.

14. The method of claim 9 ,

wherein the node is a user device.

Continuity (2)
Provisional Application 63244815 · Sep 16, 2021
Related Publication 20230083642A1 · Mar 16, 2023
References Cited (25)
US 11003791B2 · Wang · 2021 [cited by examiner]
US 20120185921A1 · Wechsler · 2012 [cited by examiner]
US 20190236300A1 · Guo · 2019 [cited by examiner]
US 20200084046A1 · Bessonov et al. · 2020 [cited by applicant]
US 20210334769A1 · Kress · 2021 [cited by examiner]
US 20240370577A1 · Jarvis · 2024 [cited by examiner]
G. Zyskind, O. Nathan and A. ′. Pentland, “Decentralizing Privacy: Using Blockchain to Protect Personal Data,” 2015 IEEE Security and Privacy Workshops, San Jose, CA, USA, 2015, pp. 180-184, doi: 10.1109/SPW.2015.27. (Y… [cited by examiner]
Extended European Search Report issued in corresponding European Patent Application No. EP 22195721.0 dated Feb. 1, 2023 (7 pages). [cited by applicant]
Ballon, Ian C., “Mobile and Internet Contract Formation and Enforcement,” E-Commerce and Internet Law: Legal Tratise with Forms, 2nd Edition, Chapter 21, Thomson/West Publishing, updated Apr. 2020 (133 pages). [cited by applicant]
Bitar, Hadi, and Björn Jakobsson, “GDPR: Securing Personal Data in Compliance with new EU-Regulations,” Luleå University of Technology, 2017 (71 pages). [cited by applicant]
“Guide on Good Data Protection Practice in Research,” European University Institute, Jul. 2021 (31 pages). [cited by applicant]
Groschopf, Wolfram, et al., “Smart Contracts for Sustainable Supply Chain Management: Conceptual Frameworks for Supply Chain Maturity Evaluation and Smart Contract Sustainability Assessment,” Frontiers in Blockchain vol… [cited by applicant]
Kamarinou, Dimitra, et al., “Machine Learning with Personal Data,” Queen Mary University of London, School of Law, Available at SSRN: https://ssrn.com/abstract=2865811, Nov. 2016 (23 pages). [cited by applicant]
Korff, Douwe, “The Territorial (and Extra-Territorial) Application of the GDPR with Particular Attention to Groups of Companies Including Non-EU Companies and to Companies and Groups of Companies that Offer Software-as-… [cited by applicant]
Matzutt, Roman, et al., “Poster: I Don't Want That Content! On the Risks of Exploiting Bitcoin's Blockchain as a Content Store,” ACM SIGSAC Conference on Computer and Communications Security, Oct. 2016 (4 pages). [cited by applicant]
Matzutt, Roman, et al., “A Quantitative Analysis of the Impact of Arbitrary Blockchain Content on Bitcoin,” Communication and Distributed Systems, RWTH Aachen University, and Data Protection Research Institute, Goethe U… [cited by applicant]
Mulligan, Stephen P., et al., “Data Protection Law: An Overview,” Congressional Research Service, Mar. 25, 2019 (79 pages). [cited by applicant]
Nica, Octabian, et al., “Cryptocurrencies: Economic benefits and risks,” University of Manchester, FinTech working paper No. 2, Oct. 26, 2017 (56 pages). [cited by applicant]
Pournaras, Evangelos, “Proof of Witness Presence: Blockchain Consensus for Augmented Democracy in Smart Cities,” Elsevier, Jul. 8, 2020 (19 pages). [cited by applicant]
Pupillo, Lorenzo, et al., “Artificial Intelligence and Cybersecurity: Technology, Governance and Policy Challenges,” CEPS Task Force Report, Center for European Policy Studies, May 2021 (122 pages). [cited by applicant]
Swan, Melanie, “Blockchain: Blueprint for a New Economy,” O'Reilly Media, Inc., Feb. 2015 (149 pages). [cited by applicant]
Templin, Sarah, “Blocked-Chain: The Application of the Unauthorized Practice of Law to Smart Contracts,” The Georgetown Journal of Legal Ethics, vol. 32, 2019 (17 pages). [cited by applicant]
Tseng, Cheng-Te, and Shari S. C. Shang, “Exploring the Sustainability of the Intermediary Role in Blockchain,” Sustainability, 13(4), 2021 (21 pages). [cited by applicant]
Tsukerman, Misha, “The Block is Hot: A Survey of the State of Bitcoin Regulation and Suggestions for the Future,” Berkeley Technology Law Journal, vol. 30, Issue 4, 2015 (44 pages). [cited by applicant]
Wachter, Sandra, et al., “Counterfactual Explanations Without Opening the Black Box: Automated Decisions and the GDPR,” Harvard Journal of Law & Technology, vol. 31, No. 2, Spring 2018 (47 pages). [cited by applicant]